{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-070-keep-host-maintenance-deferral-inside-its-supported-resource-and-time-limits/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-070-keep-host-maintenance-deferral-inside-its-supported-resource-and-time-limits/",
        "slug": "dse-20260909-070-keep-host-maintenance-deferral-inside-its-supported-resource-and-time-limits",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-070-keep-host-maintenance-deferral-inside-its-supported-resource-and-time-limits/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-070-keep-host-maintenance-deferral-inside-its-supported-resource-and-time-limits.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-070-keep-host-maintenance-deferral-inside-its-supported-resource-and-time-limits/"
        },
        "title": "Keep host maintenance deferral inside its supported resource and time limits",
        "summary": "How much control does a host-scope Azure Maintenance Configuration provide?",
        "format": {
            "slug": "checklist",
            "name": "Checklist"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:30:46+00:00",
        "modified_at": "2026-09-10T00:35:07+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 256,
        "potentially_affected": "Owners planning host-scope Maintenance Configurations for isolated Azure VMs, isolated scale sets, or dedicated hosts.",
        "dse_recommendation": "Schedule the eligible host updates within the documented deferral limit and keep rack maintenance outside that promise.",
        "primary_source": {
            "name": "Overview of Maintenance Configurations for Azure virtual machines - Azure Virtual Machines | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/virtual-machines/maintenance-configurations",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Host-scope Azure Maintenance Configurations manage platform updates that do not require a restart on isolated VMs, isolated scale sets, and dedicated hosts. They permit scheduling within 35 days; afterward, updates are applied automatically. The maintenance window must be at least two hours, and rack-level maintenance is not supported. Using Maintenance Configurations also requires an appropriate Contributor-level role and subscription registration with the maintenance resource provider. <a href=\"https://learn.microsoft.com/en-us/azure/virtual-machines/maintenance-configurations\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Confirm that the resource and intended update belong to the host scope. Keep guest package patching and scale-set OS image replacement outside this plan. Identify the workload&#8217;s interruption tolerance and the owner who can approve a host update within the available scheduling horizon.</p>\n<h2>DSE recommendation</h2>\n<p>Schedule the eligible host updates within the documented deferral limit and keep rack maintenance outside that promise. Give the maintenance calendar an explicit latest-action date and an owner for missed windows. Review the supported scope before telling an application team that all infrastructure work can be postponed. Coordinate workload preparation with the host update rather than relying on the configuration name as an availability guarantee.</p>\n<h2>Verification</h2>\n<p>Inspect the assigned resource, maintenance scope, and planned window before the approved operation. Record the observed update state and application behavior afterward. If a window is missed, compare the remaining deferral period with the recovery plan and escalate promptly. Preserve unsupported or out-of-scope maintenance events separately so the record distinguishes a failed configuration from a type of maintenance the feature does not control.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/virtual-machines/maintenance-configurations\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Managing VM updates with Maintenance Configurations</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nHost-scope Azure Maintenance Configurations manage platform updates that do not require a restart on isolated VMs, isolated scale sets, and dedicated hosts. They permit scheduling within 35 days; afterward, updates are applied automatically. The maintenance window must be at least two hours, and rack-level maintenance is not supported. Using Maintenance Configurations also requires an appropriate Contributor-level role and subscription registration with the maintenance resource provider. Microsoft Learn.\nApplicability\nConfirm that the resource and intended update belong to the host scope. Keep guest package patching and scale-set OS image replacement outside this plan. Identify the workload’s interruption tolerance and the owner who can approve a host update within the available scheduling horizon.\nDSE recommendation\nSchedule the eligible host updates within the documented deferral limit and keep rack maintenance outside that promise. Give the maintenance calendar an explicit latest-action date and an owner for missed windows. Review the supported scope before telling an application team that all infrastructure work can be postponed. Coordinate workload preparation with the host update rather than relying on the configuration name as an availability guarantee.\nVerification\nInspect the assigned resource, maintenance scope, and planned window before the approved operation. Record the observed update state and application behavior afterward. If a window is missed, compare the remaining deferral period with the recovery plan and escalate promptly. Preserve unsupported or out-of-scope maintenance events separately so the record distinguishes a failed configuration from a type of maintenance the feature does not control.\nOfficial references\nMicrosoft Learn: Managing VM updates with Maintenance Configurations. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nHost-scope Azure Maintenance Configurations manage platform updates that do not require a restart on isolated VMs, isolated scale sets, and dedicated hosts. They permit scheduling within 35 days; afterward, updates are applied automatically. The maintenance window must be at least two hours, and rack-level maintenance is not supported. Using Maintenance Configurations also requires an appropriate Contributor-level role and subscription registration with the maintenance resource provider. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/maintenance-configurations).\n\n## Applicability\n\nConfirm that the resource and intended update belong to the host scope. Keep guest package patching and scale-set OS image replacement outside this plan. Identify the workload’s interruption tolerance and the owner who can approve a host update within the available scheduling horizon.\n\n## DSE recommendation\n\nSchedule the eligible host updates within the documented deferral limit and keep rack maintenance outside that promise. Give the maintenance calendar an explicit latest-action date and an owner for missed windows. Review the supported scope before telling an application team that all infrastructure work can be postponed. Coordinate workload preparation with the host update rather than relying on the configuration name as an availability guarantee.\n\n## Verification\n\nInspect the assigned resource, maintenance scope, and planned window before the approved operation. Record the observed update state and application behavior afterward. If a window is missed, compare the remaining deferral period with the recovery plan and escalate promptly. Preserve unsupported or out-of-scope maintenance events separately so the record distinguishes a failed configuration from a type of maintenance the feature does not control.\n\n## Official references\n\n[Microsoft Learn: Managing VM updates with Maintenance Configurations](https://learn.microsoft.com/en-us/azure/virtual-machines/maintenance-configurations). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-070-keep-host-maintenance-deferral-inside-its-supported-resource-and-time-limits/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-070-keep-host-maintenance-deferral-inside-its-supported-resource-and-time-limits/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-070-keep-host-maintenance-deferral-inside-its-supported-resource-and-time-limits/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Keep host maintenance deferral inside its supported resource and time limits",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-070-keep-host-maintenance-deferral-inside-its-supported-resource-and-time-limits/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-070-keep-host-maintenance-deferral-inside-its-supported-resource-and-time-limits/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-070-keep-host-maintenance-deferral-inside-its-supported-resource-and-time-limits/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-070-keep-host-maintenance-deferral-inside-its-supported-resource-and-time-limits/",
                "headline": "Keep host maintenance deferral inside its supported resource and time limits",
                "description": "How much control does a host-scope Azure Maintenance Configuration provide?",
                "abstract": "How much control does a host-scope Azure Maintenance Configuration provide?",
                "articleBody": "Source facts\nHost-scope Azure Maintenance Configurations manage platform updates that do not require a restart on isolated VMs, isolated scale sets, and dedicated hosts. They permit scheduling within 35 days; afterward, updates are applied automatically. The maintenance window must be at least two hours, and rack-level maintenance is not supported. Using Maintenance Configurations also requires an appropriate Contributor-level role and subscription registration with the maintenance resource provider. Microsoft Learn.\nApplicability\nConfirm that the resource and intended update belong to the host scope. Keep guest package patching and scale-set OS image replacement outside this plan. Identify the workload’s interruption tolerance and the owner who can approve a host update within the available scheduling horizon.\nDSE recommendation\nSchedule the eligible host updates within the documented deferral limit and keep rack maintenance outside that promise. Give the maintenance calendar an explicit latest-action date and an owner for missed windows. Review the supported scope before telling an application team that all infrastructure work can be postponed. Coordinate workload preparation with the host update rather than relying on the configuration name as an availability guarantee.\nVerification\nInspect the assigned resource, maintenance scope, and planned window before the approved operation. Record the observed update state and application behavior afterward. If a window is missed, compare the remaining deferral period with the recovery plan and escalate promptly. Preserve unsupported or out-of-scope maintenance events separately so the record distinguishes a failed configuration from a type of maintenance the feature does not control.\nOfficial references\nMicrosoft Learn: Managing VM updates with Maintenance Configurations. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:30:46+00:00",
                "dateModified": "2026-09-10T00:35:07+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-070-keep-host-maintenance-deferral-inside-its-supported-resource-and-time-limits/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-070-keep-host-maintenance-deferral-inside-its-supported-resource-and-time-limits/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Keep host maintenance deferral inside its supported resource and time limits"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Checklist",
                    "Information priority"
                ],
                "genre": "Checklist",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 256,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Overview of Maintenance Configurations for Azure virtual machines - Azure Virtual Machines | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/virtual-machines/maintenance-configurations"
                }
            }
        ]
    }
}